Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\hlkrptky] 'ImagePath' = '%WINDIR%\hlkrptky.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\hlkrptky] 'Start' = '00000002'
- '%WINDIR%\hlkrptky.exe' "" "<Full path to virus>"
- '%WINDIR%\hlkrptky.exe'
- <SYSTEM32>\config\systemprofile\KeyF64.txt
- %WINDIR%\ssleay32.dll
- %WINDIR%\hlkrptky.exe
- <SYSTEM32>\config\systemprofile\FilesSystemLogSave.ini
- 'pa#####zielona.waw.pl':80
- http://pa#####zielona.waw.pl/images/core.php?99#####################
- DNS ASK pa#####zielona.waw.pl